Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 10
No
1

A Method for Measuring of Block-based Programming Code Quality SCOPUS

Kil Young Kwon, Won-Sung Sohn

보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.10 No.9 2016.09 pp.205-216

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The block-based programming tool is used widely for the beginner and provides several positive features compare than text-based programming language tools. To measure quality of programming code elaborately which is based script language, it is need to very tough manual process. As a result the previously research related with evaluation of block-based script code has been focused very simple methods in which normalize the number of blocks used which is related with programming concept. This study proposes the framework that can measure the quality of block-based programming script, and can analyze the level of vulnerability. At the framework, the quality metric conceptualize various programming concepts contained in block-based programming languages. In this framework, the quality metrics is constructed to structuralize implicit programming concept and then developed the quality measure and vulnerability model of script to improve level of programming. Consequently, the proposed methods enable to check of level of programming and predict the heuristic target level. The proposed method in this study was applied to the scripts derived from the scratch programming classes in Universities of Education during the last 7 years, so as to confirm the differentiation from the preceding evaluation model and studies and to verify the usefulness and superiority of the proposed model.

2

Risk Prediction of Malicious Code-Infected Websites by Mining Vulnerability Features SCOPUS

Taek Lee, Dohoon Kim, Hyunchoel Jeong, Hoh Peter In

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.1 2014.01 pp.291-294

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Malicious-code scanning tools are practically available for identifying suspicious websites. However, such tools only warn users about suspicious sites and do not provide clues as to why the sites were hacked and which vulnerability was responsible for the attack. In addition, the huge number of alarms burdens mangers while executing in-time-response duties. In this paper, a process involving feature modeling and data-mining techniques is proposed to help solve such problems.

3

추상구문트리 메타모델을 통한 코드의 보안 취약성 가시화 KCI 등재

손현승, 김영철

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.14 No.1 2017.02 pp.21-32

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

최근 정보 시스템들이 해킹되어 개인정보 유출 사고가 빈번하게 발생함에 따라 정부는 시큐어 코딩 가이드를 제정하고 전자정부 관련 정보화 사업에 의무적으로 적용하도록 하였다. 그러나 일반개발자가 시큐어 코딩의 모든 소프트웨어의 취약점을 알고 구현하기란 쉽지 않다. 그리고 기 개발된 소프트웨어에 취약점이 있는지 확인하기는 어렵다. 그러므로 소스코드 레벨에서 보안 취약성을 자동으로 분석하고 그 결과를 가시화하는 기술이 필요하다. 본 논문에서는 소프트웨어의 가시화 기술을 시큐어 코딩에 적용하여 보다 쉽게 보안 취약성을 분석할 수 있는 방법을 제안한다.

Recently, as information systems have been hacked and personal information leakage accidents have occurred frequently, the korea government enacted a secure coding guide and made it mandatory for informatization projects related to the electronic government. However, it is not easy for general developers to know and implement all software vulnerabilities in secure coding. Also, it is difficult to check for vulnerabilities in previously developed software. Therefore, there is a need for techniques to automatically analyze security vulnerabilities at the source code level and visualize the results. In this paper, we propose a method to analyze security vulnerability more easily by applying software visualization technology to secure coding.

4

DEVELOPMENT OF A VULNERABILITY ASSESSMENT CODE FOR A PHYSICAL PROTECTION SYSTEM: SYSTEMATIC ANALYSIS OF PHYSICAL PROTECTION EFFECTIVENESS (SAPE)

Jang, Sung-Soon, Kwan, Sung-Woo, Yoo, Ho-Sik, Kim, Jung-Soo, Yoon, Wan-Ki

[Kisti 연계] 한국원자력학회 Nuclear Engineering and Technology Vol.41 No.5 2009 pp.747-752

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

A vulnerability assessment is essential for the efficient operation of a physical protection system (PPS). Previous assessment codes have used a simple model called an adversary sequence diagram. In this study, the use of a two-dimensional (2D) map of a facility as a model for a PPS is suggested as an alternative approach. The analysis of a 2D model, however, consumes a lot of time. Accordingly, a generalized heuristic algorithm has been applied to address this issue. The proposed assessment method was implemented to a computer code; Systematic Analysis of physical Protection Effectiveness (SAPE). This code was applied to a variety of facilities and evaluated for feasibility by applying it to various facilities. To help upgrade a PPS, a sensitivity analysis of all protection elements along a chosen path is proposed. SAPE will help to accurately and intuitively assess a PPS.

5

안드로이드 코드서명의 취약점을 이용한 악성 앱에 관한 연구

박경용, 조태남

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2013 pp.568-571

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

스마트 폰의 보급량이 증가함에 따라 모바일 악성코드의 위협도 높아졌다. 여러 스마트 폰 플랫폼 중 안드로이드 플랫폼은 높은 점유율과 개방형 플랫폼이라는 특성상 다른 플랫폼에 비해 악의적인 공격에 취약하다. 안드로이드 앱이 스마트 폰에 설치, 실행되기 위해서는 개발자의 서명이 요구된다. 안드로이드 서명체계는 다중 서명을 허용하는데, 다중서명 체계상 악용될 수 있는 취약점이 존재한다. 본 연구에서는 안드로이드 코드서명의 취약점을 이용하여 악성코드를 실행시키고 다른 앱을 감염시키는 악성 앱을 개발하여 취약점의 악용 가능성에 대해 연구하였다.

6

소스 코드 취약점 탐지를 위한 서브워드 토큰화 기반의 딥러닝 모델

김재경

[NRF 연계] 글로벌경영학회 글로벌경영학회지 Vol.19 No.3 2022.06 pp.47-64

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The study of vulnerability detection in source code has been attracting attention in practice and academia because web applications can be vulnerable to attacks from the outside due to the open access characteristics. This study aims to build deep learning models and evaluate their performances for the field of source code vulnerability detection. The proposed deep learning models tackle class imbalance problem, long-term dependency problem, and out-of-vocabulary problem which are challenging problems in detecting source code vulnerabilities. As an experiment result, the precision of the subword tokenization-based one-dimensional convolution model showed 39%, which is about 20 times higher than the expected precision of 1.92% of the model predicted by chance. Although Conv1d+BT model using the BERT tokenizer showed the highest AUC value of 0.9116, the precision and recall of this model were 0.39 and 0.35, so it is judged that further improvement is needed for practical application.

7

산업제어시스템의 소스코드 보안 취약점 검증 룰 선정을 위한 평가 기준 개발

김은비, 최이수, 한동준

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2021 pp.449-452

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

산업제어시스템은 IT 기술의 발전에 따라 다양한 기기 환경과 네트워크를 적용해 진화하고 있다. 이러한 상황에서 사이버 보안의 위협은 가중되고 있으며, 이를 예방하는 방법의 하나로 산업제어시스템에 탑재되는 소프트웨어의 소스코드 개발 과정에서 보안 취약점을 예방하기 위해 소스코드 보안 룰을 적용하여 위반사항을 제거한다. 본 연구에서는 소스코드 보안 룰에서 적용 우선순위를 선정하기 위한 가이드를 개발한다.

8

소스코드 기반 소프트웨어 취약점 평가 자동화 방안 연구

송준호, 박재표, 권현수, 전문석

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2015 pp.794-796

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 연구는 소프트웨어의 소스코드를 대상으로 보안 취약성을 자동으로 평가할 수 있는 방안을 연구하여 소프트웨어 취약점 관리의 자동화 기술 아키텍처를 제안한다. IT가 생활환경의 기반기술로 보급화 되며 소프트웨어시장이 가파르게 성장하고 있다. 영리 소프트웨어의 경우 개발기관에서 관리 및 지원을 하지만, 오픈소스 소프트웨어는 비영리 목적과 개발환경으로 인해 체계적으로 관리되기가 어려워 취약점이 발생하기 쉽다. 그럼에도 비용과 효율의 문제로 오픈소스가 광범위하게 활용되고 있어, 오픈 소스 소프트웨어를 도입한 기관 및 단체에 침해를 유발하고, 보안수준을 악화시키고 있다. 이에 오픈 소스 소프트웨어는 소스코드가 공개되는 소프트웨어라는 점을 활용하여 소스코드 수준에서의 취약점 관리 자동화를 지원함으로써, 오픈소스 소프트웨어를 활용하는 분야의 보안 환경을 안전하게 향상시킬 수 있다.

9

어셈블리 언어 수준에서의 소스코드 보안취약점 점검방법에 관한 연구

박현미, 이병권, 박정현, 이형봉

[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2001 pp.102-110

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

대부분의 해킹 공격은 공격 대상 프로그램의 소스코드 보안취약점에 의해서 발생하지만 프로그램 개발시에 소스코드 보안성에 대해서는 고려되지 않았다. 이러한 문제점으로 인하여 해킹 공격의 근본적인 원인을 해결할 수 없었다. 본 논문에서는 취약점의 원인이 되는 코드를 컴파일시 생성된 어셈블리 코드 수준에서 탐지하는 방법을 제시하고자 한다. 취약한 코드를 컴파일러 수준에서 점검하는 것보다 어셈블리 코드 수준에서 점검하는 것은 어느 정도의 메모리 영역까지 점검할 수 있어 더 정확하다.

10

C언어 소스코드 보안 취약점 탐지를 위한 LSTM 딥러닝 하이브리드 모델의 성능 비교 분석: GNN, CNN, GRU

이예빈, 신다령, 장인주, 최은정

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.3 2026 pp.949-958

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

C언어의 메모리 직접 접근 특성으로 발생하는 보안 취약점 탐지를 위해, 본 논문은 LSTM의 한계를 보완하는 하이브리드 딥러닝 모델들을 비교 분석하였다. LSTM을 기반으로 CNN, GRU, GNN을 각각 결합한 모델들을 소스코드에 적용하였으며, 탐지 성능을 다각도로 분석하기 위해 클래스 불균형 조건에서 성능을 실험적으로 평가하였다. 실험 결과, 소스코드의 전역적 문맥과 CPG(코드 속성 그래프) 기반의 구조적 정보를 적응형 게이트(Adaptive Gate)로 융합한 LSTM-GNN 모델('CPGate Keeper' 프레임워크)이 가장 뛰어난 성능을 보였다. 이를 통해 구조 중심적 하이브리드 접근법이 LSTM 경로가 추출한 '문맥 정보'와 GNN이 추출한 '구조적 특징' 중 탐지에 더 결정적인 요소가 무엇인지 모델이 스스로 판단하게 노이즈와 오탐을 최소화할 수 있다.

This paper compared and analyzed hybrid deep learning models that complement the limitations of LSTM in order to detect security vulnerabilities arising from the direct access characteristics of memory in C language. Based on LSTM, models that combine CNN, GRU, and GNN were applied to the source code, and the performance was experimentally evaluated under class imbalance conditions to analyze the detection performance from various angles. As a result of the experiment, the LSTM-GNN model ('CPGate Keeper' framework), which combines the global context of the source code and structural information based on CPG (code attribute graph) with an adaptive gate, showed the best performance. Through this, the structure-oriented hybrid approach can minimize noise and false positives so that the model can judge for itself what is more decisive in detection among the 'contextual information' extracted by the LSTM path and the 'structural features' extracted by GNN.

 
페이지 저장